ChainShell is a JavaScript and Node.js implant associated with MuddyWater, an Iranian state-sponsored threat group. It has been documented in operations targeting defense, energy, government, and telecommunications organizations, including victims in Israel, the Middle East, the United States, and Europe. The malware has been linked to overlap between Iranian espionage activity and the TAG-150 criminal malware-as-a-service ecosystem, illustrating the use of commercially developed tooling by a state actor.
ChainShell is deployed as part of a staged intrusion chain in which a PowerShell-based deployer installs the implant on compromised hosts. Once executed, the malware retrieves its command-and-control endpoint from an Ethereum smart contract, then uses that information to obtain additional JavaScript payloads for execution. Communications are conducted over AES-encrypted WebSocket channels, providing a degree of resilience and obfuscation in command-and-control operations. The implant therefore functions as a flexible post-compromise agent capable of fetching and running follow-on code under operator control.
Attribution of ChainShell activity has been supported by operational overlaps with MuddyWater infrastructure and tooling, including code-signing artifacts and campaign identifiers associated with other MuddyWater operations. Reporting has also noted exposure of both ChainShell-related components and TAG-150 CastleRAT samples on the same misconfigured command-and-control infrastructure, reinforcing the assessment that MuddyWater acted as a customer of a multi-tenant Russian malware service while conducting intelligence collection. This convergence can complicate incident response because detections resembling ordinary criminal malware activity may in some cases represent Iranian espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater leveraged CastleRAT MaaS and ChainShell from the TAG-150 criminal ecosystem to target defense, energy, government, and telecommunications organizations in Israel, the Middle East, the US, and Europe.
Central to the operations is a PowerShell deployer ("reset.ps1") that deploys a previously undocumented JavaScript-based malware called ChainShell, which then contacts a smart contract on the Ethereum blockchain to retrieve a C2 address and use it to fetch next-stage JavaScript code for execution on compromised hosts.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The novel ChainShell payload, a JavaScript and Node.js implant, retrieves its C2 address from an Ethereum smart contract and communicates via AES-encrypted WebSocket channels.
Central to the operations is a PowerShell deployer ("reset.ps1") that deploys a previously undocumented JavaScript-based malware called ChainShell, which then contacts a smart contract on the Ethereum blockchain to retrieve a C2 address and use it to fetch next-stage JavaScript code for execution on compromised hosts.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware from the TAG-150 criminal ecosystem used by MuddyWater in targeted intrusions.
A Node.js agent in the same threat cluster that resolves command-and-control infrastructure via an Ethereum smart contract. The content notes no shared code with DinDoor.
A JavaScript and Node.js implant used in the documented campaign; it retrieves command-and-control infrastructure from an Ethereum smart contract and uses AES-encrypted WebSocket communications.
Previously undocumented JavaScript-based malware that uses an Ethereum smart contract to retrieve C2 information and fetch next-stage payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.